
Cloud Vulnerability DB
A community-led vulnerabilities database
In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a code execution attack is possible through object injection via an insecure type resolution vulnerability. The vulnerability was discovered by Markus Wulftange with CODE WHITE GmbH and has been assigned CVE-2024-8014 with a CVSS v3.1 base score of 8.8 (HIGH) (NVD, Telerik Advisory).
The vulnerability is classified as CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection'). The issue allows for code execution through object injection via an insecure type resolution vulnerability. The CVSS v3.1 vector string is AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, indicating network accessibility, low attack complexity, and high impact on confidentiality, integrity, and availability (NVD).
The vulnerability has a high severity rating due to its potential impact on system security. If exploited, it could allow attackers to execute arbitrary code through object injection, potentially compromising the affected system's confidentiality, integrity, and availability (Telerik Advisory).
The vulnerability requires network access and low attack complexity to exploit. The attacker needs low privileges and no user interaction to execute the attack, making it relatively straightforward to exploit for attackers who can reach the affected system (NVD).
Progress Telerik recommends upgrading to version 2024 Q3 (18.2.24.924) or later to address this vulnerability. Users can verify their current version either by checking the REST service endpoint /api/reports/version/ or by examining PC Settings > Installed Apps > Telerik Reporting details (Telerik Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."